Attackers compromised eight PHP packages on Packagist by injecting malware hosted on GitHub, exploiting the supply chain to potentially infect applications that depend on these libraries. You should immediately audit your dependencies on Packagist for any
Read the full article: https://thehackernews.com/2026/05/packagist-supply-chain-attack-infects-8.html